Malware

Should I remove “Malware.AI.3288772448”?

Malware Removal

The Malware.AI.3288772448 is considered dangerous by lots of security experts. When this infection is active, you may notice unwanted processes in Task Manager list. In this case, it is adviced to scan your computer with GridinSoft Anti-Malware.

GridinSoft Anti-Malware

Gridinsoft Anti-Malware

Removing PC viruses manually may take hours and may damage your PC in the process. We recommend using GridinSoft Anti-Malware for virus removal. Allows to complete scan and cure your PC during the trial period.
6-day free trial available.

What Malware.AI.3288772448 virus can do?

  • SetUnhandledExceptionFilter detected (possible anti-debug)
  • Behavioural detection: Executable code extraction – unpacking
  • Creates RWX memory
  • Dynamic (imported) function loading detected
  • CAPE extracted potentially suspicious content
  • The binary contains an unknown PE section name indicative of packing
  • Authenticode signature is invalid

Related domains:

all.fingersleep.bid
none.coalrate.men

How to determine Malware.AI.3288772448?


File Info:

name: 0F98B8BACF13599145B3.mlw
path: /opt/CAPEv2/storage/binaries/22d3d3cbfa8b6bfac61ff040253d0e5a6857e706ed676104d59ecda93dca580e
crc32: FF38D6BE
md5: 0f98b8bacf13599145b3bdf78d750081
sha1: a91a4a021ffa01751f7163b7ef5ce8837327bcbf
sha256: 22d3d3cbfa8b6bfac61ff040253d0e5a6857e706ed676104d59ecda93dca580e
sha512: 2b8af954c7084572569347fcadabbc23f51260813678d87b56603e6594a9a738b133a4daa95e7873dba5b71dfbc8518564b57d2fdb75bbacb1f5a6990ed16b87
ssdeep: 24576:Wn57Ck9EURHYi8vXG6g+3Q5qZ3YrQT2WbgZJ+E8u2UU:Wn57CM3bmW6DQ5qP2Wbp2U
type: PE32 executable (GUI) Intel 80386, for MS Windows
tlsh: T19AA5F0016F0DC125E4A69AFB5526A7083A257C1273F9ECC333D27E2E1676AC39671E13
sha3_384: d2977ea3565eb41a622dfe547d271fabfcf44872eb16491ed5c557f6168f2c5b562c8005ee103755f63550086b839a45
ep_bytes: e89c250000e97ffeffffcccccccccccc
timestamp: 2015-08-25 00:48:33

Version Info:

FileVersion: 3.8.5.5
ProductVersion: 3.8.5.5
ProductName: KUITISGO
OriginalFilename: kuitisgo.exe
LegalCopyright: ©Osenaawr
CompanyName: ©Osenaawr
InternalName: KUITISGO.EXE
Translation: 0x0409 0x04e4

Malware.AI.3288772448 also known as:

BkavW32.AIDetect.malware1
Elasticmalicious (high confidence)
MicroWorld-eScanApplication.Bundler.iStartSurf.1.Gen
FireEyeGeneric.mg.0f98b8bacf135991
ALYacApplication.Bundler.iStartSurf.1.Gen
VIPRETrojan.Win32.Generic!BT
K7AntiVirusTrojan ( 0053ba2f1 )
BitDefenderApplication.Bundler.iStartSurf.1.Gen
K7GWTrojan ( 0053ba2f1 )
Cybereasonmalicious.acf135
CyrenW32/Kryptik.CVO.gen!Eldorado
SymantecML.Attribute.HighConfidence
ESET-NOD32a variant of Win32/Kryptik.GJAJ
APEXMalicious
Paloaltogeneric.ml
Kasperskynot-a-virus:HEUR:Downloader.Win32.Generic
AlibabaDownloader:Win32/Kryptik.c3536386
NANO-AntivirusTrojan.Win32.Kryptik.fgmnax
RisingTrojan.Kryptik!1.B33C (CLASSIC)
Ad-AwareApplication.Bundler.iStartSurf.1.Gen
EmsisoftApplication.Bundler.iStartSurf.1.Gen (B)
ComodoApplication.Win32.Dlhelper.GJ@8137f9
DrWebTrojan.Vittalia.17914
ZillyaTrojan.Kryptik.Win32.1555951
SophosMal/Generic-S + Mal/EncPk-AOA
IkarusPUA.Dlhelper
GDataApplication.Bundler.iStartSurf.1.Gen
JiangminDownloader.Generic.uof
AviraHEUR/AGEN.1101341
Antiy-AVLTrojan/Win32.Kryptik
ArcabitApplication.Bundler.iStartSurf.1.Gen
CynetMalicious (score: 100)
AhnLab-V3Malware/Win32.Generic.C2665504
Acronissuspicious
McAfeePacked-FKC!0F98B8BACF13
MAXmalware (ai score=100)
VBA32BScope.Trojan.Vittalia
MalwarebytesMalware.AI.3288772448
PandaTrj/Genetic.gen
TencentMalware.Win32.Gencirc.10c9c9c8
SentinelOneStatic AI – Malicious PE
eGambitUnsafe.AI_Score_90%
FortinetW32/Kryptik.GJJV!tr
BitDefenderThetaGen:NN.ZexaF.34294.aI0@ae62dvni
AVGFileRepMalware
AvastFileRepMalware
CrowdStrikewin/malicious_confidence_90% (D)
MaxSecureTrojan.Malware.300983.susgen

How to remove Malware.AI.3288772448?

Malware.AI.3288772448 removal tool
  • Download and install GridinSoft Anti-Malware.
  • Open GridinSoft Anti-Malware and perform a “Standard scan“.
  • Move to quarantine” all items.
  • Open “Tools” tab – Press “Reset Browser Settings“.
  • Select proper browser and options – Click “Reset”.
  • Restart your computer.

About the author

Paul Valéry

I'm a cyber security analyst and data science expert with 5+ years of experience with security software contractors.

Leave a Comment